How device farms defeat SMS verification at signup
What the attackers actually run
A SIM farm is a rack of modems holding hundreds or thousands of SIM cards, each able to receive texts. A device farm is the companion: rows of real phones running scripted signup flows, each phone paired with numbers from the SIM farm. Together they complete SMS verification the honest way, by receiving the actual code on an actual device, which is why the verification passes. The code did its job. The job was just too small.
Number-rental services lower the bar further. For well under a dollar, an attacker rents a real number for ten minutes, receives the code, and discards the number. The economics favor the attacker at every step: verification costs the business money per SMS, while the bypass costs the attacker less than the SMS itself.
Why SMS was never identity proof
SMS verification answers one question: does the requester control this phone number right now? It does not answer whether the requester is a person, whether the number belongs to them, or whether they will still control it tomorrow. Number portability, VoIP numbers, and prepaid SIMs with no identity attached all widen the gap between controlling a number and being a person.
Interception attacks widen it further. SIM swapping moves the victim's number to the attacker's SIM, and SS7 weaknesses let sophisticated attackers reroute texts. But most signup fraud never needs interception: renting a fresh number is cheaper, quieter, and fully within the rules of the verification flow.
Checks that actually bind an account to a person
Device attestation is the strongest replacement: cryptographic proof from the phone's secure hardware that the device is genuine and the app is unmodified. It defeats emulators and most device farms, because the attestation cannot be faked without real hardware. Behavioral risk scoring adds the second layer: farms produce machine-regular timing and interaction patterns that stand out against human signup behavior.
For higher-risk products, document verification with liveness binds the account to a real identity document and a real face. The right level depends on what the account unlocks: a quote needs less than a bound policy, and the verification cost should scale with the fraud exposure, not with tradition.
A layered signup that holds up
Keep SMS in the stack if you like, but demote it to a contact-verification step: it proves the number works, nothing more. Gate account creation on device attestation where available, score every signup behaviorally, and step up to document checks when the risk score or the product value justifies it. Log which layer caught each rejected signup, so you can see which defenses earn their cost and which are decorative.
The attackers industrialized signup years ago. The defenses need to assume the code will be received and ask what else has to be true before the account exists.